CVE-2026-44863: Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44863?
CVE-2026-44863 has a high severity rating due to its potential for authenticated remote code execution.
How do I fix CVE-2026-44863?
To mitigate CVE-2026-44863, users should apply the available security patches released for AOS-8 and AOS-10.
Who is affected by CVE-2026-44863?
CVE-2026-44863 affects users of AOS-8 and AOS-10 operating systems with specific versions of the software.
What type of vulnerability is CVE-2026-44863?
CVE-2026-44863 is classified as an SQL injection vulnerability that allows for remote code execution.
Are there any workarounds for CVE-2026-44863?
While updating the software is the best solution, temporary measures may include limiting user permissions and auditing database access.